icon

We found results for “

CVE-2020-8927

Good to know:

icon
icon

Date: September 15, 2020

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.

Language: RUST

Severity Score

Related Resources (44)

Severity Score

Weakness Type (CWE)

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-120

Improper Handling of Length Parameter Inconsistency

CWE-130

Top Fix

icon

Upgrade Version

Upgrade to version brotli - 1.0.9;brotli - 1.0.8;microsoft.netcore.app.runtime.linux-arm - 3.1.23;microsoft.netcore.app.runtime.linux-arm - 5.0.15;microsoft.netcore.app.runtime.linux-arm - 6.0.3;microsoft.netcore.app.runtime.linux-arm64 - 3.1.23;microsoft.netcore.app.runtime.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.linux-musl-arm64 - 3.1.23;microsoft.netcore.app.runtime.linux-musl-arm64 - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm64 - 6.0.3;microsoft.netcore.app.runtime.linux-x64 - 3.1.23;microsoft.netcore.app.runtime.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.osx-x64 - 3.1.23;microsoft.netcore.app.runtime.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.win-arm - 3.1.23;microsoft.netcore.app.runtime.win-arm - 5.0.15;microsoft.netcore.app.runtime.win-arm - 6.0.3;microsoft.netcore.app.runtime.win-arm64 - 3.1.23;microsoft.netcore.app.runtime.win-arm64 - 5.0.15;microsoft.netcore.app.runtime.win-arm64 - 6.0.3;microsoft.netcore.app.runtime.win-x64 - 3.1.23;microsoft.netcore.app.runtime.win-x64 - 5.0.15;microsoft.netcore.app.runtime.win-x64 - 6.0.3;microsoft.netcore.app.runtime.win-x86 - 3.1.23;microsoft.netcore.app.runtime.win-x86 - 5.0.15;microsoft.netcore.app.runtime.win-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-arm - 5.0.15;microsoft.netcore.app.runtime.mono.linux-arm - 6.0.3;microsoft.netcore.app.runtime.mono.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-musl-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-musl-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.browser-wasm - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm - 6.0.3;microsoft.netcore.app.runtime.linux-musl-x64 - 5.0.15;microsoft.netcore.app.runtime.linux-musl-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.ios-arm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.ios-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.maccatalyst-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.maccatalyst-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvos-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.browser-wasm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.osx-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.win-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.win-x86 - 6.0.3;microsoft.netcore.app.runtime.osx-arm64 - 6.0.3

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): LOW
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): LOW
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us